Commit 61564b7c32
Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success
Layout: unified · split
CHANGELOG.org +50
| @@ -4,6 +4,56 @@ Versioning follows semver from v0.1.0. Database migrations run | |||
| 4 | automatically on daemon start; upgrade notes appear per release when | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | anything beyond "replace the binary and restart" is needed. | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | ||
| 7 | * v1.13.2 — 2026-09-04 | ||
| 8 | |||
| 9 | The first SonarCloud scan's findings: eight fixed, the rest triaged and | ||
| 10 | dismissed with reasons. | ||
| 11 | |||
| 12 | - A pages directory redirect could leave the site. Both redirects passed | ||
| 13 | the raw request path to =http.Redirect= while the cleaned path sat a | ||
| 14 | line above; =net/url= keeps a leading =//=, and Go emits | ||
| 15 | =Location: //evil.example/= unchanged, which a browser reads as | ||
| 16 | protocol-relative. Reaching it needed a public repository named like a | ||
| 17 | host under the subdomain's own owner — repository names permit dots — | ||
| 18 | so it was narrow rather than impossible. The destination is built from | ||
| 19 | the cleaned path through =url.URL= now, which also settles the two | ||
| 20 | spellings the first fix missed: a =..= that escapes to the root, and a | ||
| 21 | backslash, which browsers following the WHATWG rules treat as a | ||
| 22 | separator. #153 | ||
| 23 | - The runner's default workspace was =<tmp>/gitbay-runner=: a fixed name | ||
| 24 | in a world-writable directory, created with =MkdirAll=, which succeeds | ||
| 25 | against a directory whoever already owns it. bay1 was never exposed — | ||
| 26 | its unit names a workspace — but the default is what anyone running the | ||
| 27 | binary by hand gets, and this is the process that clones repositories | ||
| 28 | and exports build secrets. The default moves under the user's cache | ||
| 29 | directory, the workspace is created 0700, and a symlink or a directory | ||
| 30 | owned by someone else is refused. One we own that is merely too | ||
| 31 | permissive is tightened rather than refused, since every runner before | ||
| 32 | this one made it 0755 and refusing would take the runner down on | ||
| 33 | upgrade. #153 | ||
| 34 | - Logout and flash consumption expire their cookies with the attributes | ||
| 35 | the setting calls used. Deletion worked either way; the difference was | ||
| 36 | a reviewer's puzzle, and four findings. #153 | ||
| 37 | - The topics-remove field has a label. A placeholder is not an accessible | ||
| 38 | name. TestEveryInputHasAnAccessibleName is the guard that was missing, | ||
| 39 | and it knows both associations — six inputs use | ||
| 40 | =<label>Name <input></label>=, which is as good as for/id. #153 | ||
| 41 | - git and ssh are resolved once at start-up rather than searched on every | ||
| 42 | spawn, and gitbayd refuses to start when one is absent instead of | ||
| 43 | failing on whichever request first needed it. This was 74 of the 118 | ||
| 44 | findings; a dashboard that is mostly permanent noise is one nobody | ||
| 45 | reads. #153 | ||
| 46 | |||
| 47 | Also: SQLite migrations are excluded from analysis. They were read as | ||
| 48 | PL/SQL, where ='' is NULL=, so =WHERE col = ''= on a =NOT NULL DEFAULT ''= | ||
| 49 | column — correct SQLite, and the shape used throughout — read as a | ||
| 50 | null-comparison bug. | ||
| 51 | |||
| 52 | Replace the binary and reinstall the CLI. No migration. A runner whose | ||
| 53 | workspace is group- or world-readable will have it tightened to 0700 on | ||
| 54 | next start, and will refuse to start if that workspace is a symlink or | ||
| 55 | belongs to another user. | ||
| 56 | |||
| 7 | * v1.13.1 — 2026-09-04 | 57 | * v1.13.1 — 2026-09-04 |
| 8 | 58 | ||
| 9 | A command that reads its payload from stdin says so, and SonarCloud runs | 59 | A command that reads its payload from stdin says so, and SonarCloud runs |